Vulnerabilities / Threats
9/14/2011
12:42 PM
50%
50%

Social Engineering Leads APT Attack Vectors

Combat advanced persistent threats with more adaptive user training and by acknowledging that networks today exist in a state of constant compromise, say experts.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
The number-one advanced persistent threat (APT) attack vector is now not technology, but social engineering. Furthermore, security is no longer about trying to keep all intruders outside of the network perimeter, but rather acknowledging that security today involves living in a state of constant compromise.

Those are some key findings that came out of a summit held in Washington last week by RSA, the security division of EMC, as well as TechAmerica, a technology trade association. The summit involved about 100 "c-level" managers--CIOs, CTOs, and a few CEOs--plus senior lawyers, all drawn from large, well-known businesses and government agencies, who were gathered to discuss the best way to combat APTs.

"It wasn't some vendor-driven thing," said Eddie Schwartz, CSO of RSA, in an interview. Rather, he said, it was aimed at updating current approaches to security, in light of the types of advanced--and oftentimes, persistent and hard-to-detect--threats that have successfully exploited numerous organizations, including RSA.

One of the summit's major findings is that social engineering attacks are now the primary threat vector used to compromise businesses and government agencies. But as employees have become much more of a risk, what hasn't changed, said Schwartz, is "the degree to which anything had been done about it, or investments shifted, or program emphasis shifted, versus just spending money on perimeter security technologies."

Another interesting finding from the summit was that many businesses and government agencies said that while pursuing a "zero breach tolerance" approach was nice in theory, it's now unrealistic. "A more realistic [approach] would be accepting the fact that you live in a world of compromise, and understanding that you have to work in that world, and work in a mode of triage, instead of constantly trying to push back hordes at the gate," said Schwartz.

One driver for that more pragmatic worldview has been the emergence of targeted malware that is, in some cases, just hours old. Combating this type of APT can be incredibly difficult, because all it takes is one employee to open a seemingly innocuous--yet really malicious--attachment, and the business can be compromised.

Attackers' ability to hit big businesses and government agencies with never-before-seen malware implies that attackers often benefit from significant resources. "This increased agility on the part of attackers shows a very high level of resources available to them, where they can have people who are very responsive to the defenses of large organization ... and be able to work around those organizations on a case by case basis," said Schwartz. "So they're highly focused, and very agile to what the target is trying to do to defend itself."

What can be done to deal with these types of attacks? Given the threat posed by social engineering, Schwartz said that one of the more innovative--and adaptive--approaches described was wargaming, in which employees face real-world tests, such as their ability to avoid a spear-phishing attack. Fail the test, and they're called into a room to see, as a group, what the consequences of that attack would have been--both for them, and their employer.

Another strategy that could help organizations better resist APTs would be some form of information sharing, such as crowdsourcing attack data. "Today's attackers are better at real-time intelligence sharing than we, the targets are. In other words, they're better at gathering open source intelligence about us, organizing the data, and collaborating with each other, than we are at defending ourselves," said Schwartz.

Unfortunately, sharing information between defenders faces numerous hurdles, including the need for indemnification against liability, some sort of underlying technical infrastructure, as well as the current lack of "a standard set of nouns, verbs, and adjectives" to describe security attacks, said Schwartz. "Really, there aren't these types of lexicons today for communicating at machine speed about these types of problems."

Security professionals often view compliance as a burden, but it doesn't have to be that way. In this report, we show the security team how to partner with the compliance pros. Download the report here. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
JuneSanchez
50%
50%
JuneSanchez,
User Rank: Apprentice
10/8/2011 | 8:16:06 PM
re: Social Engineering Leads APT Attack Vectors
Great Article. After watching the social engineering experts from Ioactive Mike Ridpath (@ridpath) and Matias Brutti (@freedomcoder) talk on Social Engineering myself and few others within my company are in the process of creating more adaptive user training.

Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-8626
Published: 2014-11-22
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding...

CVE-2014-8710
Published: 2014-11-22
The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

CVE-2014-8711
Published: 2014-11-22
Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allow remote attackers to cause a denial of service (application crash) via a crafted amqp_0_10 PDU in a packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?